{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.170-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.85-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.19.11-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  mm/huge_memory: fix folio isn't locked in softleaf_to_folio()  On arm64 server, we found folio that get from migration entry isn't locked in softleaf_to_folio().  This issue triggers when mTHP splitting and zap_nonpresent_ptes() races, and the root cause is lack of memory barrier in softleaf_to_folio().  The race is as follows:  \tCPU0                                             CPU1  deferred_split_scan()                              zap_nonpresent_ptes()   lock folio   split_folio()     unmap_folio()       change ptes to migration entries     __split_folio_to_order()                         softleaf_to_folio()       set flags(including PG_locked) for tail pages    folio = pfn_folio(softleaf_to_pfn(entry))       smp_wmb()                                        VM_WARN_ON_ONCE(!folio_test_locked(folio))       prep_compound_page() for tail pages  In __split_folio_to_order(), smp_wmb() guarantees page flags of tail pages are visible before the tail page becomes non-compound.  smp_wmb() should be paired with smp_rmb() in softleaf_to_folio(), which is missed.  As a result, if zap_nonpresent_ptes() accesses migration entry that stores tail pfn, softleaf_to_folio() may see the updated compound_head of tail page before page-\u003eflags.  This issue will trigger VM_WARN_ON_ONCE() in pfn_swap_entry_folio() because of the race between folio split and zap_nonpresent_ptes() leading to a folio incorrectly undergoing modification without a folio lock being held.  This is a BUG_ON() before commit 93976a20345b (\"mm: eliminate further swapops predicates\"), which in merged in v6.19-rc1.  To fix it, add missing smp_rmb() if the softleaf entry is migration entry in softleaf_to_folio() and softleaf_to_page().  [tujinjiang@huawei.com: update function name and comments]",
  "id": "DEBIAN-CVE-2026-31466",
  "modified": "2026-09-14T16:47:26.864136139Z",
  "published": "2026-04-22T14:16:42.780Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-31466"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-31466"
  ]
}